AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15360

CRITICAL · CVSS 9.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Ajax Load More WordPress plugin prior to version 8.0.1 is vulnerable to time-based blind SQL injection due to inadequate sanitization and escaping of user-supplied parameters in SQL queries. This flaw allows unauthenticated attackers to potentially extract sensitive data from the database, posing a significant risk to the integrity and confidentiality of the site's information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-15360
Severity
CRITICAL
CVSS
9.1
EPSS
0.32%
WordPress

Original NVD Description

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.